-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Incident Response in the Age of Cloud
By :

Let's discuss a few tools that can make IR in the cloud easier for you.
Developed and maintained by Google, GRR is an open source IR framework for performing live, remote forensic analyses with threat hunting capabilities.
GRR is composed of a server, which issues instructions, and a client, which is deployed on your systems and waits for directions from the server. It's scalable and flexible.
The following screenshot from the tool demonstrates its easy-to-use hunting capabilities:
Figure 5.14: GRR hunting
You can download GRR from GitHub: grr-doc.readthedocs.io.
Malware Information Sharing Platform (MISP) enables you to collect, store, and share information about cybersecurity threats, indicators, and analyses. It can provide support for SIEMs, network IDSes, and the Linux Intrusion Detection System.
It has a database of incident indicators, an automatic...
Change the font size
Change margin width
Change background colour